PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | modules/infinite-scroll/infinity.php +2 -32 16.3 → 16.3-beta View file →
@@ -1657,45 +1657,15 @@
1657 1657 );
1658 1658
1659 1659 if ( isset( $_REQUEST['query_args'] ) && is_array( $_REQUEST['query_args'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
1660 1660 foreach ( wp_unslash( $_REQUEST['query_args'] ) as $var => $value ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitized below.
1661 - if ( ! in_array( $var, $allowed_vars, true ) || empty( $value ) ) {
1662 - continue;
1661 + if ( in_array( $var, $allowed_vars, true ) && ! empty( $value ) ) {
1662 + $query_args[ $var ] = filter_var( $value );
1663 1663 }
1664 -
1665 - if ( 'post_type' === $var && ! self::is_queryable_post_type( $value ) ) {
1666 - continue;
1667 - }
1668 -
1669 - $query_args[ $var ] = filter_var( $value );
1670 1664 }
1671 1665 }
1672 1666
1673 1667 return $query_args;
1674 - }
1675 -
1676 - /**
1677 - * Whether a post type supplied with the request may be queried on the front end.
1678 - *
1679 - * Core applies this test to the main query in WP::parse_request(), but the
1680 - * Infinite Scroll query is a secondary one and never passes through it.
1681 - *
1682 - * @param mixed $post_type Post type name, or array of names, from the request.
1683 - * @return bool
1684 - */
1685 - private static function is_queryable_post_type( $post_type ) {
1686 - // WP_Query expands 'any' to the types that opted into search results.
1687 - if ( 'any' === $post_type ) {
1688 - return true;
1689 - }
1690 -
1691 - foreach ( (array) $post_type as $type ) {
1692 - if ( ! is_string( $type ) || ! is_post_type_viewable( $type ) ) {
1693 - return false;
1694 - }
1695 - }
1696 -
1697 - return true;
1698 1668 }
1699 1669
1700 1670 /**
1701 1671 * Rendering fallback used when themes don't specify their own handler.